A path traversal vulnerability exists in Esri ArcGIS Earth versions 1.11.0 and below which allows arbitrary file creation on an affected system through crafted input. An attacker could exploit this vulnerability to gain arbitrary code execution under security context of the user running ArcGIS Earth by inducing the user to upload a crafted file to an affected system.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Esri

Published: 2021-05-05T15:16:13.177240Z

Updated: 2024-09-16T18:34:30.244Z

Reserved: 2021-03-23T00:00:00

Link: CVE-2021-29100

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-05-05T16:15:07.987

Modified: 2023-11-07T03:32:28.673

Link: CVE-2021-29100

cve-icon Redhat

No data.